Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Redhat2Fedora LibvirtJun 17, 2026 May 22, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-adm...Show more |
5Canonical DebianFedoraproject+2 more7Backports Sle Debian LinuxFedora+4 moreJun 17, 2026 May 20, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a SEGV in the SDL function SDL_free_REAL at stdlib/SDL_malloc.c. |
4Canonical DebianFedoraproject+1 more5Debian Linux FedoraSdl2 Image+2 moreJun 17, 2026 May 20, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a heap-based buffer overflow in the SDL2_image function IMG_LoadPCX...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraFreeimage+1 moreJun 17, 2026 May 20, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 When FreeImage 3.18.0 reads a special TIFF file, the TIFFReadDirectory function in PluginTIFF.cpp always returns 1, leading to stack exhaustion. |
6Artifex CanonicalDebian+3 more6Debian Linux Enterprise LinuxFedora+3 moreJun 17, 2026 May 16, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have acces...Show more |
4Debian FedoraprojectHeimdal Project+1 more5Backports Sle Debian LinuxFedora+2 moreJun 17, 2026 May 15, 2019 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c. |
5Fedoraproject HpeNetapp+2 more6Clustered Data Ontap Data OntapFedora+3 moreJun 17, 2026 May 15, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 NTP through 4.2.8p12 has a NULL Pointer Dereference. |
5Canonical DebianFedoraproject+2 more15Debian Linux Enterprise LinuxEnterprise Linux Desktop+12 moreJun 17, 2026 May 15, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local users to obtain sensitive information by reading uninitialized data in the...Show more |
3Fedoraproject OpensuseSylabs4Backports FedoraLeap+1 moreJun 17, 2026 May 14, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered in Singularity 3.1.0 to 3.2.0-rc2, a malicious user with local/network access to the host system (e.g. ssh) could exploit this vulnerability due to insecure permissions allowing a user to edit fil...Show more |
3Fedoraproject OpensuseRust Lang3Fedora LeapRustJun 17, 2026 May 13, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's safety guarantees and cause memory unsafety. If the `Error::type_id` method is ove...Show more |
6Canonical DebianFedoraproject+3 more12Debian Linux Enterprise LinuxEnterprise Linux Eus+9 moreJun 17, 2026 May 10, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNADD command, because a...Show more |
5Debian DrupalFedoraproject+2 more5Debian Linux DrupalFedora+2 moreJun 17, 2026 May 9, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as de...Show more |
3Dovecot FedoraprojectOpensuse3Dovecot FedoraLeapJun 17, 2026 May 8, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the client disconnects prematurely during the AUTH command. |
3Dovecot FedoraprojectOpensuse3Dovecot FedoraLeapJun 17, 2026 May 8, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login component crashes if AUTH PLAIN is attempted over a TLS secured channel with an unacceptable authentication message. |
3Fedoraproject KdeOpensuse4Backports FedoraKauth+1 moreJun 17, 2026 May 7, 2019 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of arbitrary images with...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLeap+3 moreJun 17, 2026 May 3, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to in...Show more |
3Debian FedoraprojectFilezilla Project3Debian Linux FedoraFilezilla ClientJun 17, 2026 Apr 29, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's home directory. |
4Canonical FedoraprojectNetapp+1 more7Cn1610 Firmware FedoraHci Management Node+4 moreJun 17, 2026 Apr 26, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker m...Show more |
7Canonical DebianFedoraproject+4 more14Active Iq Unified Manager For Vmware Vsphere Cn1610 FirmwareDebian Linux+11 moreJun 17, 2026 Apr 25, 2019 N/A· v4 7.7 HIGH· v3 6.8 MEDIUM· v2 An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other...Show more |
6Canonical DebianFedoraproject+3 more13Active Iq Unified Manager For Vmware Vsphere Cn1610 FirmwareDebian Linux+10 moreJun 17, 2026 Apr 24, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administra...Show more |